CVE-2026-0303
Received Received - Intake

Arbitrary Code Execution in Checkov by Prisma Cloud

Vulnerability report for CVE-2026-0303, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-10

Last updated on: 2026-09-10

Assigner: Palo Alto Networks, Inc.

Description

A code execution vulnerability in Palo Alto Networks Checkov by Prismaยฎ Cloud can allow arbitrary code execution when Checkov scans a directory that contains an attacker-controlled configuration file.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-10
Last Modified
2026-09-10
Generated
2026-09-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
palo_alto_networks checkov From 3.2.0 (inc) to 3.2.531 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-829 The product imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
AI Quick Actions have not been generated yet.

Chat Assistant

Ask questions about this CVE
Hi! Iโ€™m here to help you understand CVE-2026-0303. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart